High severity8.8NVD Advisory· Published Apr 27, 2026· Updated Apr 30, 2026
CVE-2026-7078
CVE-2026-7078
Description
A security flaw has been discovered in Tenda F456 1.0.0.5. The impacted element is the function fromSetIpBind of the file /goform/SetIpBind of the component httpd. The manipulation of the argument page results in buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Affected products
1- cpe:2.3:o:tenda:f456_firmware:1.0.0.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/Litengzheng/vuldb_new/blob/main/F456/vul_129/README.mdnvdExploitThird Party Advisory
- vuldb.com/submit/798460nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/359653nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/359653/ctinvdPermissions RequiredVDB Entry
- www.tenda.com.cnnvdProduct
News mentions
0No linked articles in our index yet.